Openkruise is a Kubernetes workload management and automation project focused on the Kruise controller, which operates within containerized infrastructure to manage application deployment and lifecycle operations. The vulnerability footprint reflects the privileged operational context of this component, clustering around privilege-escalation weaknesses including unnecessary privilege execution, improper privilege management, and server-side request forgery that can arise in orchestration and control-plane adjacent code. Current severity, exploitation status, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Openkruise over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24005HIGH Kruise provides automated management of large-scale applications on Kubernetes. Prior to versions 1.8.3 and 1.7.5, PodProbeMarker allows defining custom probes with TCPSocket or HT | Feb 25, 2026 | 7.6 | 24 | NO | NO |
CVE-2023-30617MEDIUM Kruise provides automated management of large-scale applications on Kubernetes. Starting in version 0.8.0 and prior to versions 1.3.1, 1.4.1, and 1.5.2, an attacker who has gained | Jan 3, 2024 | 6.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Openkruise.
Media articles that mention a CVE ID that affects a product developed by Openkruise — matched by CVE ID, not by vendor name.